Skip to main content

wkdhash

Calculate Web-Key-Directory hashes of OpenPGP UIDs.

The Web-Key-Directory (WKD) is a method for deploying OpenPGP public keys for an email address through HTTPS.

For this, the keys user IDs are decomposed into their mailbox local part (the thing before the @ sign). This is then sha1 hashed and z-base-32 encoded, resulting in the "hu" (hashed user-id, I guess?).

The public key is then made available under a well-known URL containing the hu. So to deploy your public key to your webserver, you have to figure out what your uid's hu is. This can be done with

gpg --list-keys --with-wkd-hash $IDENTITY

but it is not easily doable from Python when using python-gnupg.

API

A single function is the only thing you really need:

from wkdhash import userid_to_wkd_hash

assert(userid_to_wkd_hash("mail@example.com") == "dizb37aqa5h4skgu7jf1xjr4q71w4paq")
assert(userid_to_wkd_hash("Test User <mail@example.com>", include_domain=True) == "dizb37aqa5h4skgu7jf1xjr4q71w4paq@example.com")

Command-line-utility

A simple command line utility entry-point is provided by this package, which reads user IDs from an input stream (default stdin) and writes the hu to an output stream (default stdout). So this module can also be used for bash scripting.

usage: wkdhash [-h] [-F] [-o outfile] [infile]

Read OpenPGP User IDs line-by-line and print their corresponding Web-Key-Directory hashed-user-id (hu).

positional arguments:
  infile                Input OpenPGP UserID, defaults to stdin

options:
  -h, --help            show this help message and exit
  -F, --full            If set, output 'hu@domain', instead of just 'hu'
  -o, --output outfile  Output, default stdout

MIT License, Copyright (c) 2025 Gregor Vollmer

Example Usage

$ echo "mail@example.com" | poetry run wkdhash
dizb37aqa5h4skgu7jf1xjr4q71w4paq
$ echo "Test User <mail@example.com>" | poetry run wkdhash -F
dizb37aqa5h4skgu7jf1xjr4q71w4paq@example.com
$ poetry run wkdhash
mail@example.com^Ddizb37aqa5h4skgu7jf1xjr4q71w4paq

Metadata

Release files for wkdhash 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for wkdhash 0.1.0
File Size Uploaded
wkdhash-0.1.0.tar.gz 4.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for wkdhash 0.1.0
File Interpreter ABI Platform
wkdhash-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 11.8 kB

Release files / wkdhash-0.1.0.tar.gz

Download URL wkdhash-0.1.0.tar.gz
Size 4.0 kB
Tags Source
SHA-256 checksum
How to use checksums
4560c2f02fbac9be421373fe9a1f67d11d0ac9d48f5f1b91f704a6cb1714aa59
BLAKE2b-256 checksum
How to use checksums
632f886077028785719817d195a7d73d7559feb6c397accc85b5b0f4c57f431b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.1.1 CPython/3.13.2 Linux/6.13.2-arch1-1

Release files / wkdhash-0.1.0-py3-none-any.whl

Download URL wkdhash-0.1.0-py3-none-any.whl
Size 7.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ca9f3d4bdfff6b13a4effdde1ffcb2cc6ca888e0a8dc34b1e88fe3dc9719a035
BLAKE2b-256 checksum
How to use checksums
b1d1df10cd72f3beaa2b502c45c34cb2b00c293c51768443a1874f30bd1f9471
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.1.1 CPython/3.13.2 Linux/6.13.2-arch1-1

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page